Repository navigation
Commit 8e426bb
fix(deps): upgrade pillow to 12.3.0 for security fixes
Resolves multiple high/medium severity Dependabot alerts: heap
out-of-bounds writes in ImageCmsTransform.apply(), Image.paste()/crop()
and ImageFilter.RankFilter, a JPEG2000 tiled-decode DoS, a decompression
bomb in PdfParser, a TGA RLE encoder heap data leak, an OS command
injection in WindowsViewer.get_command(), several decompression-bomb
check bypasses (GdImageFile, BdfFontFile, FontFile, PcfFontFile), an
out-of-bounds read via row stride on the mmap path, and an infinite
loop DoS in EpsImagePlugin.
GHSA-9hw9-ch79-4vh6, GHSA-vjc4-5qp5-m44j, GHSA-jjj6-mw9f-p565,
GHSA-6r8x-57c9-28j4, GHSA-fj7v-r99m-22gq, GHSA-xj96-63gp-2gmr,
GHSA-4x4j-2g7c-83w6, GHSA-phj9-mv4w-65pm, GHSA-45hq-cxwh-f6vc,
GHSA-5x94-69rx-g8h2, GHSA-8v84-f9pq-wr9x, GHSA-62p4-gmf7-7g93,
GHSA-pg7v-jwj7-p798
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>1 parent f5cbf26 commit 8e426bb
2 files changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
140 | 140 | | |
141 | 141 | | |
142 | 142 | | |
143 | | - | |
| 143 | + | |
144 | 144 | | |
145 | 145 | | |
146 | 146 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
120 | | - | |
| 120 | + | |
121 | 121 | | |
122 | 122 | | |
123 | 123 | | |
| |||
0 commit comments